HARDEN
Reduce verified security exposure in a vulnerable or misconfigured environment while keeping required services operational.
Explore Harden ↗The 2026 format paired four-person teams with three tracks: Harden, Hack, and Hunt. This archive preserves the scoring method and published prize plan.
THREE DIFFERENT SECURITY PERSPECTIVES
CyberShield is one connected team competition made up of three distinct environments. Teams harden a defensive environment, attack a target network, and investigate evidence from a simulated incident.
The environments are designed around related professional skills.
Archived programReduce verified security exposure in a vulnerable or misconfigured environment while keeping required services operational.
Explore Harden ↗Discover attack paths, exploit weaknesses, pivot through a target environment, and capture validated objectives.
Explore Hack ↗Analyze evidence, reconstruct activity, identify indicators, and determine what happened during a simulated incident.
Explore Hunt ↗Each track may use a different number of available points. To make the results comparable, every track score is first normalized to 100. The confirmed track weights are then applied.
Hack contributes 50% of the final score. Harden and Hunt each contribute 25%.
Verified improvement after the post-hardening assessment.
Validated flags and required evidence submitted through CTFd.
Correct investigative findings submitted through CTFd.
Complete validated hardening checks, flags, and investigative objectives.
Track points earned ÷ track points available × 100.
Multiply each normalized result by 25%, 50%, or 25%.
Add the three weighted results to determine the overall ranking.
(Harden × 0.25) + (Hack × 0.50) + (Hunt × 0.25)
Illustrative examples from the published scoring guidance, not actual team results.
20 + 40 + 20 = 80.0
15 + 47.5 + 17.5 = 80.0
17.5 + 45 + 20 = 82.5
Organizers assess the template environment before the challenge. After time expires, each team environment is scanned. Points reflect verified reduction in weighted security weaknesses while required services remain available.
Teams earn points through CTFd for valid flags and required evidence obtained inside the authorized target environment. Higher-value objectives may require deeper access or several connected steps.
Teams earn points through CTFd for correct investigative findings, validated artifacts, and accurate conclusions drawn from the provided incident evidence.
The published method used post-challenge assessment for Harden rather than a live flag-based score.
The assessment process compared each hardened environment with the baseline, checked required services, and calculated a normalized result.
Organizers assess the template environment before the event.
Teams make security improvements during the challenge.
Organizers scan and validate each team environment after time expires.
The verified score is normalized to 100 and added to the final ranking.
The published weights were 25% / 50% / 25%. The source page did not include the final service checks, penalties, score-lock process, or tie-break order.
FOUR IDENTICAL BUNDLES · SIXTEEN ITEMS
The published prize plan allocated one CyberShield Team Prize Bundle to each of the top four teams, with four practical technology items per bundle.
Training and certification opportunities were also listed for the top three teams. Providers and award conditions were not confirmed in the published source. This page does not confirm prize delivery.
Compact USB-C charger with cable.
Ethernet, HDMI, power delivery, and USB connectivity.
Rotating aluminum desktop riser.
Compact crossbody bag with secure storage.
THE STORY CONTINUES